High 7.8
KEV-listed
CVE-2019-2215
French Cyber Spies Hacked EncroChat Network Using GitHub Malware
Vendor / product: EncroChat phones, Android
Event date: 2020-04-01
Victim organization: not stated
Public PoC: Yes
First tracked by RiskWire: 2026-08-16
CISA KEV catalog
Added to KEV
Federal remediation due
2022-05-03 (1601 days overdue)
Ransomware campaign use
Unknown
CISA description
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
Required action
Apply updates per vendor instructions.
Named threat actors
C3NSTNCJ
Sources & citations (1)
- Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network computerweekly.com · 2026-08-17
References
See CVE-2019-2215 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →